> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/netflow-ddos-detector/interface/dashboard.md).

# Dashboard

The Netflow DDoS Detector Dashboard provides the following key metrics:

## Bandwidth <a href="#id-insights-dashboard-bandwidth" id="id-insights-dashboard-bandwidth"></a>

<figure><img src="/files/Q2Yfbrb1JoWAZEqmNfwQ" alt=""><figcaption></figcaption></figure>

### **Bandwidth by Protocol**

The Bandwidth by Protocol feature displays the amount of network bandwidth over a selected time period, categorized by specific protocols. You can hide individual protocols by clicking on them.

#### **All**

The total inbound traffic for all protocols analyzed by Netflow DDoS Detector for the relevant collector.

**UDP**

The total inbound traffic for the UDP protocol analyzed for the relevant collector.

**TCP**

The total inbound traffic for the TCP protocol analyzed for the relevant collector.

**ICMP**

The total inbound traffic for the ICMP protocol analyzed for the relevant collector.

**GRE**

The total inbound traffic for the GRE protocol analyzed for the relevant collector.

***

## Packets <a href="#id-insights-dashboard-packets" id="id-insights-dashboard-packets"></a>

<figure><img src="/files/NeawaU8jVajKw5szNgJo" alt=""><figcaption></figcaption></figure>

### **Packets by Protocol**

The Bandwidth by Protocol feature displays the amount of network packets over a selected time period, categorized by specific protocols ([listed above](#bandwidth-by-protocol)). You can hide individual protocols by clicking on them.

***

## Threats <a href="#id-insights-dashboard-threats" id="id-insights-dashboard-threats"></a>

<figure><img src="/files/SZIW5CrBbVWfqhIrYJsl" alt=""><figcaption></figcaption></figure>

DDoS Attack occurrences are represented on the Link11 Netflow DDoS Detector chart. The width of each attack segment indicates its duration.

Note: the height of the DDoS Attack indicator does not reflect the attack's size. It will adjust to fit the chart area.

***

## Destination Prefix Analysis <a href="#id-insights-dashboard-destinationprefixanalyse" id="id-insights-dashboard-destinationprefixanalyse"></a>

<figure><img src="/files/q8OWHPKqaCch3xvLviXF" alt=""><figcaption></figcaption></figure>

The Destination Prefix Analysis feature empowers admins to delve deeper into specific traffic patterns within a selected timeframe, down to an individual IP address. You can choose a specific timeframe using either the date selector or by marking the desired timeframe directly on the graph above.

Simply click on a prefix to drill down further, allowing you to explore traffic patterns of individual IP addresses within that prefix.

### Export Function <a href="#id-insights-dashboard-exportfunction" id="id-insights-dashboard-exportfunction"></a>

<div align="left"><figure><img src="/files/2O2yzkLt4TAKi9QLqMNa" alt=""><figcaption></figcaption></figure></div>

This feature generates a CSV file containing separated flows to the selected prefix within the chosen time frame. The exported file will include all flows per minute with their respective data.

{% hint style="warning" %}
Please be aware that the resulting CSV file may be quite large. We impose a limit of 1,000,000 entries in total and a maximum of 1,000,000 entries per instance (collector) divided by the number of selected instances (collectors) for your export. If you encounter missing data, we recommend considering the following options:

* Select a shorter time frame.
* Narrow down the destination IP range.
* Reduce the number of instances (collectors) chosen for export.

These adjustments will help ensure a successful export without data loss.
{% endhint %}

<figure><img src="/files/nhpYsH9Ai4YNwNb4uk7x" alt=""><figcaption></figcaption></figure>

<br>
